BriefingCMMC programReviewed July 23, 2026

Briefings · The program

The CMMC pause, explained

On July 13, 2026, the Department of Defense suspended Phase 2 of the CMMC rollout, the third-party assessment requirement scheduled for November 10, 2026, and every later milestone with it, while a Reform Task Force reviews the program. The rules underneath did not move: DFARS 252.204-7012, NIST SP 800-171, SPRS scores, and the self-assessments contracts require at award all remain in effect.

The pause · at a glance

Requirements, still binding110
SuspendedPhase 2 · July 13, 2026
Still in forceDFARS 252.204-7012
Report expectedMid-September 2026
ReviewedJuly 23, 2026

The short version

What was suspended is the gate: third-party certification as a condition of award. What was not suspended is the ground: the 110 security requirements, the clauses already in your contracts, self-assessments, annual affirmations, incident reporting, and flow-downs. If an obligation came from a contract clause, it still binds today.

The record

What actually happened

On July 13, 2026, the department announced the immediate suspension of CMMC Phase 2, which would have made certification by a third-party assessment organization (C3PAO) a condition of award for applicable contracts involving controlled unclassified information starting November 10, 2026. All pending and later implementation milestones, including the full-rollout date that would have put the CMMC clause in every applicable solicitation by November 2028, were placed in abeyance with it.

The follow-through was immediate and contractual: contracting officers were directed to include only self-assessment levels (Level 1 Self and Level 2 Self) in new solicitations during the suspension, and to remove Level 2 (C3PAO) and Level 3 (DIBCAC) assessment requirements from active solicitations and contracts by modification.

In parallel, the department stood up a CMMC Reform Task Force charged with reviewing the whole program, explicitly including whether existing commercial cybersecurity capabilities and self-attestation can carry more of the load. Its report is expected roughly 60 days from the announcement, which lands in mid-September 2026. Industry input was invited through a public request for information, due 12:00 p.m. ET on August 14, 2026.

During the review, the department stated it will continue to enforce cybersecurity compliance against NIST SP 800-171 through self-assessments and select government-led assessments.

Still binding

What still applies, clause by clause

The pause is narrower than the headlines. Here is the obligation-by-obligation picture.

CMMC-related obligations, their sources, and their status during the 2026 suspension
Obligation Where it comes from Status
15 basic safeguards for federal contract information FAR 52.204-21 In effect
All 110 NIST SP 800-171 requirements for CUI DFARS 252.204-7012 In effect
System security plan and plans of action NIST SP 800-171 via 252.204-7012 In effect
Cyber incident reporting within 72 hours DFARS 252.204-7012 In effect
Current self-assessment score in SPRS, no more than three years old DFARS 252.204-7019 Checked at award
Government assessment access and subcontractor flow-down DFARS 252.204-7020 In effect
Annual Level 1 and Level 2 self-assessments with affirmations CMMC Phase 1 (48 CFR rule, in effect since Nov 2025) In effect
C3PAO certification as a condition of award (Level 2) CMMC Phase 2 Suspended
Government-led DIBCAC certification assessments (Level 3) CMMC Phase 2+ Suspended

"Suspended" is not "repealed." The department has said contractors should not assume the suspension is the final disposition of third-party assessment requirements.

Reading it straight

What it means for a small contractor

The deadline moved; your exposure didn't. The 110 requirements are already in your contracts through DFARS 252.204-7012, and your SPRS score is a representation the government relies on at award. The Department of Justice's Civil Cyber-Fraud Initiative has already produced multi-million-dollar False Claims Act settlements over misstated cybersecurity compliance, and that enforcement runs on the clauses, not on CMMC's schedule.

Primes didn't pause. Flow-downs are contractual, and prime contractors reading the same uncertainty tend to keep asking their suppliers for evidence of readiness. A supplier who can show an operating system beats a supplier who can show a plan to have one.

Every reform outcome favors the same position. If third-party assessments return, the queue meets a pool of roughly one hundred authorized C3PAOs and preparation time becomes the scarcest asset. If the program leans harder on self-attestation, the signature on that attestation carries more legal weight, not less, and it needs an implemented, documented, operating system behind it. There is no outcome where the work is wasted.

The honest read: the pause is preparation time. Use it on the system, not the countdown. Our 93-step program exists for exactly that work, and the readiness-gaps briefing shows where that work usually starts.

Straight answers

Asked and answered

Q01

Is CMMC dead?

No. The rollout is suspended while the Reform Task Force reviews the program, with a report expected around mid-September 2026. Third-party assessments could return as they were, revised, or replaced by a leaner attestation model, and the department has explicitly not ruled the current model out. The requirements underneath stay binding either way.

Q02

Do I still need a SPRS score?

Yes. DFARS 252.204-7019 still requires a current self-assessment score, no more than three years old, posted in SPRS at time of award. The pause did not touch it, and its accuracy is what False Claims Act cases get built on.

Q03

My contract already required certification. Now what?

Contracting officers were directed to remove Level 2 (C3PAO) and Level 3 (DIBCAC) requirements from active solicitations and contracts by modification, and to include only self-assessment levels in new ones during the suspension. The change lands contract by contract, so watch your own modifications.

Q04

Should we stop preparing?

Stop preparing for a date. Keep preparing the system. Self-assessments, affirmations, and the 110 requirements continue throughout the review, and whatever the task force recommends will still be measured against the same NIST SP 800-171 ground.

Sources